In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input format string and arguments are larger than the buffer size then buffer overflow occurs. Beginning in version 0.5.0, the conversion buffers are sized correctly and checked appropriately to prevent buffer overflows.
References
Link | Resource |
---|---|
https://github.com/eclipse-omr/omr/pull/7658 | Patch Vendor Advisory |
https://gitlab.eclipse.org/security/cve-assignement/-/issues/55 | Issue Tracking Vendor Advisory |
Configurations
History
05 Mar 2025, 18:54
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CPE | cpe:2.3:a:eclipse:omr:*:*:*:*:*:*:*:* | |
First Time |
Eclipse
Eclipse omr |
|
References | () https://github.com/eclipse-omr/omr/pull/7658 - Patch, Vendor Advisory | |
References | () https://gitlab.eclipse.org/security/cve-assignement/-/issues/55 - Issue Tracking, Vendor Advisory | |
Summary |
|
21 Feb 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-21 10:15
Updated : 2025-03-05 18:54
NVD link : CVE-2025-1471
Mitre link : CVE-2025-1471
CVE.ORG link : CVE-2025-1471
JSON object : View
Products Affected
eclipse
- omr
CWE
CWE-787
Out-of-bounds Write